WordPress Plugin Vulnerabilities

Answer My Question 1.3 - SQL Injection

Description

$_POST['id'] is not escaped. Url is accessible for any user.
Url vulnerable : http://target/wp-content/plugins/answer-my-question/modal.php

Proof of Concept

Affects Plugins

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Submitter
Lenon Leite
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2016-11-17 (about 9 years ago)
Added
2016-11-21 (about 9 years ago)
Last Updated
2019-11-01 (about 6 years ago)

Other